sbp opened a new issue, #1235:
URL: https://github.com/apache/tooling-trusted-releases/issues/1235

   Some of ATR's dependencies have few maintainers or very slow release cycles. 
These dependencies are most at risk of social engineering attacks, and such 
attack would be far less likely to be discovered than attacks on dependencies 
with many maintainers and users. We should add some automated review pipelines, 
in addition to doing manual review on upgrades.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to